Skip to content

AI assessment assistant

Writing the observation is the slow part of an audit. The AI assessment assistant drafts it for you: it reads the framework, the requirement, the controls and evidence already linked to it, and produces a paragraph describing how the organisation meets the requirement — which you then edit, refine or throw away. It suggests; it never decides.

On a requirement’s edit page, below the Observation field. The panel starts collapsed to a single AI Suggest Assessment button and is hidden entirely when the audit is locked.

  1. Click AI Suggest Assessment. The panel expands and shows Gathering context and generating suggestion… while it assembles the requirement’s context.
  2. A context badge names what the assistant is working from: the Framework, the Requirement, and counts of the linked controls and evidences. If those counts are zero, the draft will be thin — link the controls first.
  3. The Suggested Observation streams into the panel as it is written, so you can start reading before it finishes.

Behind the badge, the assistant also reads the requirement’s description, annotation, typical-evidence hint and importance, the audit’s name and scoring scale, the current result and status, and any observation already recorded — so re-running it on a half-written observation refines rather than replaces.

While the draft is on screen, a text box invites you to Tell the AI what to adjust…. Type an instruction in plain language — “mention the monthly cadence of our log reviews”, “shorten to three sentences”, “name the specific policy” — and the draft is rewritten with that instruction applied. Regenerate produces a fresh take on the same context without an instruction. Both can be repeated as often as you like.

Three actions close the draft:

  • Edit and Accept — opens the text in an editor for a final pass, then writes it to the Observation field.
  • Accept — writes the suggestion to the Observation field as-is.
  • Dismiss — closes the panel and changes nothing.

Nothing reaches the requirement until you accept, and accepting only fills the form field. The requirement is saved when you save the form, so an accepted suggestion can still be discarded by cancelling out.

Once an observation is accepted the assistant offers a second pass: Would you also like the AI to suggest the following? Tick any combination of:

  • Compliance Result — Compliant, Partially compliant or Non-compliant.
  • Score — a value on the audit’s own scoring range.
  • Typical Evidence — what proof to go looking for.

Choose Generate Selected to run it, or No thanks, I’m done to stop. The result comes back as Extended Suggestions, each with a Confidence rating of High, Medium or Low and a Reasoning note explaining the call. Tick the ones you want and choose Accept Selected, or Skip to keep the observation and drop the rest.

Suggestions are rate-limited per user and per organisation each day; hitting the cap shows AI suggestion limit reached for today and the assistant becomes unavailable until the window resets. If the feature flag is off, the panel does not render and the API refuses the request, so turning it off is a complete shutdown rather than a UI change. Administrators configure the flag and the model provider in settings.

  • Audits — the requirement fields the assistant fills in.
  • Evidences — the linked proof that makes a draft worth reading.
  • Feature flags — enabling the module.
  • Settings — where the flag lives.